Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 27.6%top 2.1%

CVE-2024-38193: CWE-416: Use After Free in Microsoft Windows 11 Version 24H2

0
High
Published: 08/11/2026 (08/11/2026, 20:52:10 UTC)
Source: CVE
Vendor/Project: Microsoft
Product: Windows 11 Version 24H2

Description

The provided document does not contain an intelligence report. Instead, it appears to be a webpage notification indicating that JavaScript needs to be enabled in the browser to proceed with viewing content. The page includes a verification mechanism to confirm that the user is not an automated bot. No threat intelligence information, malicious activity, threat actors, malware campaigns, attack techniques, or cybersecurity-related content is present in the provided material. Therefore, no meaningful analysis of threat activity, targeted countries, industries, or technical indicators can be extracted from this content.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Affected software

Affected versions
=10.0.26100.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 02/28/2026, 04:29:13 UTC

Technical Analysis

CVE-2024-38193 is a use-after-free vulnerability classified under CWE-416 affecting the Windows Ancillary Function Driver for WinSock in Microsoft Windows 11 Version 24H2 (build 10.0.26100.0). Use-after-free vulnerabilities occur when a program continues to use memory after it has been freed, leading to undefined behavior such as memory corruption, crashes, or arbitrary code execution. In this case, the vulnerability allows a local attacker with limited privileges (PR:L) to elevate their privileges to higher levels without requiring user interaction (UI:N). The vulnerability has a CVSS v3.1 base score of 7.8, indicating high severity, with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). The attack vector is local (AV:L), meaning the attacker must have local access to the system, but the attack complexity is low (AC:L), making exploitation feasible without specialized conditions. The scope is unchanged (S:U), so the impact is confined to the vulnerable component and system. The vulnerability is exploitable with functional exploit code (E:F) and has official remediation (RL:O) with confirmed fixes (RC:C), although no patch links are currently provided. This vulnerability targets the Windows networking stack component responsible for socket operations, which is critical for network communication. Exploitation could allow attackers to execute arbitrary code with elevated privileges, potentially leading to full system compromise. No known exploits are currently observed in the wild, but the vulnerability's nature and impact make it a high priority for remediation.

Potential Impact

The impact of CVE-2024-38193 is significant for organizations worldwide, especially those using Windows 11 Version 24H2. Successful exploitation allows a local attacker to escalate privileges, potentially gaining SYSTEM-level access. This can lead to unauthorized access to sensitive data, installation of persistent malware, disruption of services, and complete system takeover. The vulnerability affects the networking subsystem, which is critical for communication and operations in enterprise environments. Attackers could leverage this flaw to bypass security controls, move laterally within networks, and compromise critical infrastructure. The absence of required user interaction increases the risk of automated or stealthy exploitation once local access is obtained. Organizations with remote access solutions, shared workstations, or multi-user environments are particularly vulnerable. The high impact on confidentiality, integrity, and availability underscores the need for urgent mitigation to prevent data breaches, operational disruptions, and reputational damage.

Mitigation Recommendations

1. Apply official Microsoft security updates as soon as they are released for Windows 11 Version 24H2 to address CVE-2024-38193. 2. Until patches are available, restrict local access to trusted users only and enforce the principle of least privilege to minimize potential attackers' ability to exploit the vulnerability. 3. Implement application whitelisting and endpoint detection and response (EDR) solutions to monitor and block suspicious activities related to WinSock driver operations. 4. Regularly audit and monitor system logs for unusual privilege escalation attempts or memory corruption indicators. 5. Disable or limit unnecessary network services and protocols that rely on the vulnerable WinSock driver to reduce the attack surface. 6. Employ network segmentation to isolate critical systems and reduce the risk of lateral movement by attackers exploiting this vulnerability. 7. Educate system administrators and users about the risks of local privilege escalation vulnerabilities and the importance of timely patching. 8. Use virtualization or sandboxing technologies for high-risk applications to contain potential exploitation impacts. These measures, combined with prompt patching, will significantly reduce the risk posed by this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
microsoft
Date Reserved
2024-06-11T22:36:08.217Z
Cisa Enriched
true
Cvss Version
3.1
State
PUBLISHED

Indicators of Compromise

Cve

ValueDescriptionCopy
cveCVE-2024-38193
cveCVE-2025-49113
cveCVE-2025-60719
cveCVE-2026-68820

Hash

ValueDescriptionCopy
hash13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79
hash1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c
hash21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762
hash231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858
hash29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2
hash2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8
hash2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb
hash3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6
hash396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c
hash3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a
hash3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d
hash4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9
hash4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a
hash4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105
hash4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d
hash5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d
hash590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6
hash68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb
hash6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be
hash72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289
hash743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1
hash75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1
hash82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943
hash8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c
hash92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1
hasha0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d
hasha45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2
hasha673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7
hasha738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075
hashacb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97
hashb4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb
hashba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7
hashc2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461
hashcc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222
hashd578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459
hashdb3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d
hashea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619
hashf7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d
hashfb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d
hashfecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b
hasheb0c40cefac66574d6b6e7ead832ee8b40e2d8db

Domain

ValueDescriptionCopy
domainenveil.online
domainenvell.xyz
domainuxtramine.org

Threat ID: 682cd0f81484d88663aeb297

Added to database: 05/20/2025, 18:59:04 UTC

Last enriched: 02/28/2026, 04:29:13 UTC

Last updated: 08/12/2026, 06:56:12 UTC

Views: 126

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses